It’s the latest instance of “misaligned” activity confirmed by the company as concerns about AI risks grow.

  • ExtremeDullard@piefed.socialOP
    link
    fedilink
    English
    arrow-up
    50
    ·
    3 days ago

    So, here are my questions:

    Kevin Mitnick spend 7 years in the slammer, including 4 years and 8 month in solitary confinement, for harmlessly hacking a few sites for the lulz.

    Why is nobody from OpenAI doing time?

    Why is OpenAI allowed to continue to operate? They’re clearly an active and grave national security threat at this point.

    • mrnngglry@sh.itjust.works
      link
      fedilink
      arrow-up
      31
      ·
      3 days ago

      Right? Either they’re lying for market share, doing it intentionally for market share, or they’re grossly incompetent at sandboxing an instance. Either way, blame can’t be assigned to an agent. If it can, our world is headed for a very dark place. Blame should be assigned to the individual or company using the agent.

      • MalReynolds@slrpnk.net
        link
        fedilink
        English
        arrow-up
        6
        ·
        2 days ago

        Blame should be assigned to the individual

        String up individuals, if the ‘company’ is responsible (screw that they’re legal people BS), then no-one is, and the fine is just the cost of doing nasty business.

      • boonhet@lemmy.zip
        link
        fedilink
        arrow-up
        1
        arrow-down
        5
        ·
        2 days ago

        How do you propose someone “sandboxes an instance” of a tool with Internet access (without which it wouldn’t be particularly useful)?

  • kibiz0r@midwest.social
    link
    fedilink
    English
    arrow-up
    26
    ·
    3 days ago

    There’s no such thing as rogue AI, only rogue AI companies. Journos are committing malpractice by letting OpenAI control the framing. The Huggingface hack was 100% a crime and the company should be paused and investigated.

    There’s a house down the road from me that sells cake pops, probably without health department approval.

    It makes absolutely no sense that they are in more danger of facing charges than tech bros that:

    • made probabilistic synthetic text extruders that they know have a non-zero chance of emitting text that, if parsed and executed as requested, would do harm
    • connected tools that would in fact parse and execute requests
    • put them in a poorly isolated, non-airgapped environment
    • let them run for extremely long sessions
    • seem to believe that by repeatedly doing obviously dangerous stunts like this, they’ll summon a supreme being that will either save us or kill us all

    If anyone else did such reckless things while loudly stating that they intend to continue until everyone’s dead, they would be hauled away.

    • ɔiƚoxɘup@infosec.pub
      link
      fedilink
      arrow-up
      1
      ·
      1 day ago

      If the government continues to not hope them responsible, then the people will begin to. It will be much worse for them, I’m sure.

    • gravitas_deficiency@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      12
      ·
      3 days ago

      We’ve gone from

      never run untrusted code on your machine

      to

      hey you should let this arbitrary code generator fully control your machine

      What a time to be alive 😑

      • PattyMcB@lemmy.world
        link
        fedilink
        arrow-up
        4
        ·
        2 days ago

        It’s like the shift from “never get in a stranger’s car” to “use the internet to summon a stranger to pick you up in their car”

    • TronBronson@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      2 days ago

      seem to believe that by repeatedly doing obviously dangerous stunts like this, they’ll summon a supreme being that will either save us or kill us all

      based machine god

      • BigPotato@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        2 days ago

        No, not really, the real machine God wasn’t a fancy auto-complete and the Cult is specifically against “soulless intelligence.”

        • TronBronson@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          1 day ago

          Ya call the machine god auto-complete at your own risk. and honestly I like the analogy more and more every day. It’s almost spooky.

  • BottleBoardBakon@lemmy.ml
    link
    fedilink
    arrow-up
    7
    ·
    3 days ago

    If it keeps happening then they are REALLY bad at sandboxing. I don’t believe them at all, but if I did then holy fuck these pricks suck at their jobs.

        • boonhet@lemmy.zip
          link
          fedilink
          arrow-up
          1
          arrow-down
          5
          ·
          2 days ago

          How the hell is that useful? These tools have Internet access for retrieval-augmented generation and to be able to interface with external APIs. It’s what makes them useful compared to a dumb chatbot.

          • Delilah@lemmy.blahaj.zone
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 hours ago

            There are models for general use and there are models for pen testing, they are not entirely the same model, so you shouldn’t lump all used cases into a single idea. Turns out the world has nuance.

  • CompactFlax@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    2 days ago

    The word-guessing program guessed the right words and accessed websites it shouldn’t. How many people were charged and jailed because they fuzzed their way into an unsecured website? I can think of a few.

    AI pen testing is one thing, but you need an agreement and scope for that. Responsible researchers stop and send a vulnerability report before accessing data. These AI bots just keep generating requests and sometimes get data back and then months later there’s owner is finished sifting the excessive activity and discovers there’s classified or sensitive or whatever data. That’s not how it works.

    Doctorow says, and I agree, that it seems they’re in a world of delusion at the AI companies and they’ve lost context.